CVE-2021-33489: XSS
Published Nov 22, 2021
·Updated
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
Description
Frequently Asked Questions
1
What is CVE-2021-33489?
CVE-2021-33489 is a vulnerability in OX App Suite through 7.10.5 that allows XSS (Cross-Site Scripting) attacks via JavaScript code in a shared XCF file.
2
How severe is CVE-2021-33489?
CVE-2021-33489 has a severity rating of medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2021-33489?
OX App Suite versions up to and including 7.10.5 are affected by CVE-2021-33489.
4
How can an attacker exploit CVE-2021-33489?
An attacker can exploit CVE-2021-33489 by injecting malicious JavaScript code into a shared XCF file, which can lead to Cross-Site Scripting (XSS) attacks.
5
Is there a fix for CVE-2021-33489?
Yes, updating OX App Suite to a version higher than 7.10.5 will fix the vulnerability.